CVE-2026-73621
Reported by VulnCheck · Published August 13, 2026
GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in the sibling iter_items method. An attacker who can control options passed to Commit.count (e.g., via an application that forwards a user-supplied options dict) can supply output=<path>, causing 'git rev-list --output=<path>' to open and truncate the target file to zero bytes before revision parsing. This allows destruction/blanking of an arbitrary file at the process's privilege level (no content control, 0-byte truncation).
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| gitpython-developers | GitPython | 0, 3.1.56 |
| gitpython_project | gitpython | 0, 0 |
| gitpython-developers | GitPython | 0, 3.1.56, 0 |
Timeline
- Aug 13, 2026 Coalition ESS Score
- Aug 13, 2026 CVE Published
- Aug 20, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Sep 3, 2026 CVE Updated
- Sep 4, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score
References
- GitHub Security Advisory (GHSA-p538-c434-8v24) vendor-advisory
- VulnCheck Advisory: GitPython before 3.1.56 Arbitrary File Truncation via Commit.count third-party-advisory